About WHAWIT
Paging a human is the end
of an investigation, not the start.
WHAWIT is an AI-powered observability, incident management and incident-AI platform with native on-call. It connects read-only to the monitoring tools a team already runs, investigates root cause across logs, metrics and code, and pages the responder with the analysis already attached.
Why we built it
Monitoring has become very good at two things: noticing that something is wrong, and telling somebody about it. Then it stops. The alert lands, and whoever is on call starts from a blank page — opening dashboards, scrolling logs, checking what shipped, correlating one tool against another — before they can even form a first hypothesis. The hardest, slowest part of an incident is the part the tooling hands back to a person, usually the least convenient person at the least convenient hour.
An incident should arrive at a responder with the investigation already done.
That single sentence is the product. Everything below follows from it, and anything that does not serve it does not get built.
Investigation before notification
The Radar agent works the incident across logs, metrics and code — forming a root-cause hypothesis, collecting the evidence behind it, and continuing in cycles whether or not a human is watching.
On-call is not a separate product
Schedules, timezone-aware rotating layers, overrides and escalation policies are native. Paging goes out over WhatsApp, SMS, voice call, Slack, Microsoft Teams, Discord and email.
Read-only ingestion, no rip-and-replace
WHAWIT reads from the monitoring tools already in place — GCP Cloud Logging, CloudWatch, Datadog, New Relic, Sentry, BetterStack — and the investigation writes nothing back to them. What does write is separate and connected on purpose: a ticket in your tracker, incident status mirrored into an on-call tool, or a proposed fix pushed as a branch and opened as a pull request. Letting that pull request merge on its own is an opt-in policy setting, off by default, and you choose the gate it has to pass.
It meets people where the work happens
Response is coordinated in Slack and Microsoft Teams. Tickets are created and kept in sync with Jira, GitHub, Azure DevOps and Linear; incident status syncs separately with Jira, Linear and OpsGenie. A VS Code extension and MCP server bring the investigation into the editor.
Who builds it

Jose Escrich
Founder
Jose Escrich has spent more than 25 years building and operating enterprise systems where downtime, noise and slow incident response carry real cost. WHAWIT is the tool that job kept asking for.
He runs every pilot personally: onboarding, architecture and security review, and evaluation against your real incidents before any broader rollout.
Trusted by enterprise teams



The company
WHAWIT is built and operated by US3 GROUP LLC. The details a vendor-onboarding form asks for, in one place.
- Legal entity
- US3 GROUP LLC
- Registered address
- 255 Giralda Ave, Floor 5, Coral Gables, FL 33134, United States
Trust Center
Security architecture, data handling, subprocessors and current compliance posture.
Privacy Policy
What we collect, how credentials and query data are handled, and what is never retained.
Terms of Service
The agreement that governs use of the platform.
On compliance, so it is not inferred from anything above: a SOC 2 Type I audit is targeted for Q4 2026 / Q1 2027, and WHAWIT is currently in readiness preparation. Security review materials and an architecture walkthrough are part of every pilot. Questions that belong in writing go to [email protected], and anything commercial to [email protected].
See it on your own incidents
A pilot connects read-only to the providers you already run and is evaluated against incidents that actually happened to you. Nothing is ripped out to find out whether it works.
Book a Pilot
